RegionalNatGatewayProvider
- class aws_cdk.aws_ec2.RegionalNatGatewayProvider(*, allocation_id=None, availability_zone_addresses=None, eip=None, max_drain_duration=None)
Bases:
NatProviderProvider for Regional NAT Gateways.
Regional NAT Gateways provide automatic multi-AZ redundancy with a single gateway that scales across availability zones. Unlike zonal NAT gateways, a regional NAT gateway does not require a public subnet and is created at the VPC level.
- See:
https://docs.aws.amazon.com/vpc/latest/userguide/nat-gateways-regional.html
- ExampleMetadata:
fixture=_generated
Example:
# The code below shows an example of how to instantiate this type. # The values are placeholders you should change. import aws_cdk as cdk from aws_cdk import aws_ec2 as ec2 from aws_cdk.interfaces import aws_ec2 as interfaces_ec2 # e_ip_ref: interfaces_ec2.IEIPRef regional_nat_gateway_provider = ec2.RegionalNatGatewayProvider( allocation_id="allocationId", availability_zone_addresses=[ec2.AvailabilityZoneAddress( allocation_ids=["allocationIds"], # the properties below are optional availability_zone="availabilityZone", availability_zone_id="availabilityZoneId" )], eip=e_ip_ref, max_drain_duration=cdk.Duration.minutes(30) )
- Parameters:
allocation_id (
Optional[str]) – The allocation ID of the Elastic IP address to use for this NAT gateway. Cannot be specified together witheip. Ignored whenavailabilityZoneAddressesis specified. Default: - A new EIP is automatically allocatedavailability_zone_addresses (
Optional[Sequence[Union[AvailabilityZoneAddress,Dict[str,Any]]]]) – Specifies which Availability Zones you want the NAT gateway to support and the Elastic IP addresses to use in each AZ. When specified,allocationIdandeipare ignored. This enables manual mode for Regional NAT Gateway where you control EIP allocation per AZ. In manual mode the gateway only serves the listed Availability Zones and does not expand to other zones automatically, so every Availability Zone that contains a private subnet routed through this gateway must be listed. When the zone names are known at synthesis time, a private subnet in an unlisted zone is rejected with an error. Entries that useavailabilityZoneIdor unresolved tokens cannot be checked and are assumed to be correct. Default: - Automatic mode: AWS manages AZ coverage and EIP allocationeip (
Optional[IEIPRef]) – Reference to an existing EIP to use for this NAT gateway. Cannot be specified together withallocationId. Ignored whenavailabilityZoneAddressesis specified. Default: - A new EIP is automatically allocatedmax_drain_duration (
Optional[Duration]) – Maximum amount of time to wait before forcibly releasing IP addresses if connections are still in progress. Default: Duration.seconds(350)
Methods
- configure_nat(*, nat_subnets, private_subnets, vpc)
Called by the VPC to configure NAT.
Don’t call this directly, the VPC will call it automatically.
- Parameters:
nat_subnets (
Sequence[PublicSubnet]) – The public subnets where the NAT providers need to be placed. For Regional NAT Gateways, this should be an empty array as they don’t require public subnets.private_subnets (
Sequence[PrivateSubnet]) – The private subnets that need to route through the NAT providers. There may be more private subnets than public subnets with NAT providers.vpc (
Vpc) – The VPC we’re configuring NAT for.
- Return type:
None
- configure_subnet(subnet)
Configures subnet with the gateway.
Don’t call this directly, the VPC will call it automatically.
- Parameters:
subnet (
PrivateSubnet)- Return type:
None
Attributes
- configured_gateways
Return list of gateways spawned by the provider.
A regional NAT gateway is not bound to a single Availability Zone, so
azis the sentinel string'regional'rather than a zone name.
Static Methods
- classmethod gateway(*, eip_allocation_ids=None, max_drain_duration=None)
Use NAT Gateways to provide NAT services for your VPC.
NAT gateways are managed by AWS.
- Parameters:
eip_allocation_ids (
Optional[Sequence[str]]) – EIP allocation IDs for the NAT gateways. Default: - No fixed EIPs allocated for the NAT gatewaysmax_drain_duration (
Optional[Duration]) – Maximum amount of time to wait before forcibly releasing IP addresses if connections are still in progress. Default: Duration.seconds(350)
- See:
https://docs.aws.amazon.com/vpc/latest/userguide/vpc-nat-gateway.html
- Return type:
- classmethod instance(*, instance_type, associate_public_ip_address=None, credit_specification=None, default_allowed_traffic=None, key_name=None, key_pair=None, machine_image=None, security_group=None, user_data=None)
(deprecated) Use NAT instances to provide NAT services for your VPC.
NAT instances are managed by you, but in return allow more configuration.
Be aware that instances created using this provider will not be automatically replaced if they are stopped for any reason. You should implement your own NatProvider based on AutoScaling groups if you need that.
- Parameters:
instance_type (
InstanceType) – Instance type of the NAT instance.associate_public_ip_address (
Optional[bool]) – Whether to associate a public IP address to the primary network interface attached to this instance. Default: undefined - No public IP address associatedcredit_specification (
Optional[CpuCredits]) – Specifying the CPU credit type for burstable EC2 instance types (T2, T3, T3a, etc). The unlimited CPU credit option is not supported for T3 instances with dedicated host (host) tenancy. Default: - T2 instances are standard, while T3, T4g, and T3a instances are unlimited.default_allowed_traffic (
Optional[NatTrafficDirection]) – Direction to allow all traffic through the NAT instance by default. By default, inbound and outbound traffic is allowed. If you set this to another value than INBOUND_AND_OUTBOUND, you must configure the NAT instance’s security groups in another way, either by passing in a fully configured Security Group using thesecurityGroupproperty, or by configuring it using the.securityGroupor.connectionsmembers after passing the NAT Instance Provider to a Vpc. Default: NatTrafficDirection.INBOUND_AND_OUTBOUNDkey_name (
Optional[str]) – (deprecated) Name of SSH keypair to grant access to instance. Default: - No SSH access will be possible.key_pair (
Optional[IKeyPair]) – The SSH keypair to grant access to the instance. Default: - No SSH access will be possible.machine_image (
Optional[IMachineImage]) – The machine image (AMI) to use. By default, will do an AMI lookup for the latest NAT instance image. If you have a specific AMI ID you want to use, pass aGenericLinuxImage. For example:: ec2.NatProvider.instance({ instanceType: new ec2.InstanceType(‘t3.micro’), machineImage: new ec2.GenericLinuxImage({ ‘us-east-2’: ‘ami-0f9c61b5a562a16af’ }) }) Default: - Latest NAT instance imagesecurity_group (
Optional[ISecurityGroup]) – (deprecated) Security Group for NAT instances. Default: - A new security group will be createduser_data (
Optional[UserData]) – Custom user data to run on the NAT instances. Default: UserData.forLinux().addCommands(…NatInstanceProviderV2.DEFAULT_USER_DATA_COMMANDS); - Appropriate user data commands to initialize and configure the NAT instances
- Deprecated:
- Return type:
use instanceV2. ‘instance’ is deprecated since NatInstanceProvider uses a instance image that has reached EOL on Dec 31 2023
- See:
https://docs.aws.amazon.com/vpc/latest/userguide/VPC_NAT_Instance.html
- Stability:
deprecated
- classmethod instance_v2(*, instance_type, associate_public_ip_address=None, credit_specification=None, default_allowed_traffic=None, key_name=None, key_pair=None, machine_image=None, security_group=None, user_data=None)
Use NAT instances to provide NAT services for your VPC.
NAT instances are managed by you, but in return allow more configuration.
Be aware that instances created using this provider will not be automatically replaced if they are stopped for any reason. You should implement your own NatProvider based on AutoScaling groups if you need that.
- Parameters:
instance_type (
InstanceType) – Instance type of the NAT instance.associate_public_ip_address (
Optional[bool]) – Whether to associate a public IP address to the primary network interface attached to this instance. Default: undefined - No public IP address associatedcredit_specification (
Optional[CpuCredits]) – Specifying the CPU credit type for burstable EC2 instance types (T2, T3, T3a, etc). The unlimited CPU credit option is not supported for T3 instances with dedicated host (host) tenancy. Default: - T2 instances are standard, while T3, T4g, and T3a instances are unlimited.default_allowed_traffic (
Optional[NatTrafficDirection]) – Direction to allow all traffic through the NAT instance by default. By default, inbound and outbound traffic is allowed. If you set this to another value than INBOUND_AND_OUTBOUND, you must configure the NAT instance’s security groups in another way, either by passing in a fully configured Security Group using thesecurityGroupproperty, or by configuring it using the.securityGroupor.connectionsmembers after passing the NAT Instance Provider to a Vpc. Default: NatTrafficDirection.INBOUND_AND_OUTBOUNDkey_name (
Optional[str]) – (deprecated) Name of SSH keypair to grant access to instance. Default: - No SSH access will be possible.key_pair (
Optional[IKeyPair]) – The SSH keypair to grant access to the instance. Default: - No SSH access will be possible.machine_image (
Optional[IMachineImage]) – The machine image (AMI) to use. By default, will do an AMI lookup for the latest NAT instance image. If you have a specific AMI ID you want to use, pass aGenericLinuxImage. For example:: ec2.NatProvider.instance({ instanceType: new ec2.InstanceType(‘t3.micro’), machineImage: new ec2.GenericLinuxImage({ ‘us-east-2’: ‘ami-0f9c61b5a562a16af’ }) }) Default: - Latest NAT instance imagesecurity_group (
Optional[ISecurityGroup]) – (deprecated) Security Group for NAT instances. Default: - A new security group will be createduser_data (
Optional[UserData]) – Custom user data to run on the NAT instances. Default: UserData.forLinux().addCommands(…NatInstanceProviderV2.DEFAULT_USER_DATA_COMMANDS); - Appropriate user data commands to initialize and configure the NAT instances
- See:
https://docs.aws.amazon.com/vpc/latest/userguide/VPC_NAT_Instance.html
- Return type:
- classmethod regional_gateway(*, allocation_id=None, availability_zone_addresses=None, eip=None, max_drain_duration=None)
Use a Regional NAT Gateway to provide NAT services for your VPC.
Regional NAT Gateways provide automatic multi-AZ redundancy with a single gateway that scales across availability zones. AWS automatically manages AZ coverage and EIP allocation.
- Parameters:
allocation_id (
Optional[str]) – The allocation ID of the Elastic IP address to use for this NAT gateway. Cannot be specified together witheip. Ignored whenavailabilityZoneAddressesis specified. Default: - A new EIP is automatically allocatedavailability_zone_addresses (
Optional[Sequence[Union[AvailabilityZoneAddress,Dict[str,Any]]]]) – Specifies which Availability Zones you want the NAT gateway to support and the Elastic IP addresses to use in each AZ. When specified,allocationIdandeipare ignored. This enables manual mode for Regional NAT Gateway where you control EIP allocation per AZ. In manual mode the gateway only serves the listed Availability Zones and does not expand to other zones automatically, so every Availability Zone that contains a private subnet routed through this gateway must be listed. When the zone names are known at synthesis time, a private subnet in an unlisted zone is rejected with an error. Entries that useavailabilityZoneIdor unresolved tokens cannot be checked and are assumed to be correct. Default: - Automatic mode: AWS manages AZ coverage and EIP allocationeip (
Optional[IEIPRef]) – Reference to an existing EIP to use for this NAT gateway. Cannot be specified together withallocationId. Ignored whenavailabilityZoneAddressesis specified. Default: - A new EIP is automatically allocatedmax_drain_duration (
Optional[Duration]) – Maximum amount of time to wait before forcibly releasing IP addresses if connections are still in progress. Default: Duration.seconds(350)
- See:
https://docs.aws.amazon.com/vpc/latest/userguide/nat-gateways-regional.html
- Return type: